...
All data is encrypted during transit using https/SSL. We do not encrypt email and names on server as they are required for search.
Data privacy
here..
Deleting data
We keep data for 90 days post delete company data request. After this company data will be hard deleted from the system permanently.
...
We support exporting major data (OKR, Users etc) in excel format.
Security Audits
here .We are using various tools to access security of our application. Security checklist and reports can be made available on authentic request.
Database Access
Database access on aws is configured in such a way that, even application on AWS can not access database if it is not a part of designated security group.
...
Only designated person in team can access Database. It is a short lived window and access is granted by our AWS admin, that to based on IP.
Disaster recovery
here .Although Database is secured on AWS, avoiding data loss is ours responsibility. We protect your business-critical data from loss and stay compliant and productive with a backup and restore solution. We do take daily backups to avoid any data loss in case of any disaster.
Reporting Security Vulnerabilities
...